CVE-2025-33053
Summary
A remote code execution flaw in Windows WebDAV scored CVSS 8.8, observed in campaigns that lured users to attacker WebDAV shares.
Details
The digest recorded it inside a wider WebDAV malware campaign: one live operation targeted Windows users in Mexico through a fake government ID-lookup site and exploited CVE-2025-33053 to run its payload. WebDAV is a useful delivery path precisely because Windows resolves \\host\share paths natively, so a link or shortcut can reach the attacker's share without a download prompt — the same property that makes .library-ms and search-connector files recurring phishing artefacts. Mitigation that does not depend on the patch is to block WebClient from starting as a service on hosts that do not use WebDAV.
| Attribute | Detail |
|---|---|
| CVE | CVE-2025-33053 |
| CVSS | 8.8 |
| Vendor / product | Microsoft Windows (WebDAV) |
| Reported in the digest | 2026-07-21 |
Related Pages
Sources: raw/digests/Cyber-Digest-2026-07-21.md